An attacker drained $8.07 million from crypto payment processor Coinsbuy on Aug. 9, emptying eight Tron wallets and three Ethereum wallets in under an hour, according to onchain data reviewed by blockchain security researchers. The theft opened with a 5 USDT test transaction, then took 6.04 million USDT off Tron and 1.89 million USDT plus 77 ETH off Ethereum. Coinsbuy refilled every drained wallet within 24 hours and said the affected amounts were covered in full from company reserves. It has not said how the attacker reached the withdrawal path.
A cross-chain swapper is a service that converts a token held on one blockchain into a token on another without the user opening an account at a centralized exchange. That mechanism is what tied the Coinsbuy incident together.
Key takeaways
- An attacker took $8.07 million from Coinsbuy across Tron and Ethereum on Aug. 9, draining 11 wallets in under an hour.
- Onchain records link the two chains to a single operator through cross-chain swapper Bridgers, whose Ethereum payout contract funded the attacker’s swap wallet.
- About 79% of the stolen funds moved through instant exchange FixedFloat using roughly 50 single-use addresses, with portions converted into Monero.
- Coinsbuy restored the drained wallets to within 0.05% of their pre-attack balances inside 24 hours and has published no technical postmortem.
Published: Aug. 10, 2026, 16:00 UTC
How researchers tied two chains to one attacker
Onchain records connect the Tron and Ethereum drains through Bridgers, a cross-chain swapper whose Ethereum payout contract deposited funds directly into the wallet used to swap the stolen Ethereum assets. Without that link, the two drains would read as separate incidents at separate firms.
On Tron, eight wallets gave up 6.04 million USDT over roughly an hour. On Ethereum, three wallets were emptied at the same time of 1.89 million USDT and 77 ETH, with the stablecoin routed into ETH through decentralized exchange aggregator 1inch using a wallet created that same day. The two sequences landed near-simultaneously, which is difficult to arrange without shared access to both sides of the platform’s wallet infrastructure.
The activity was flagged by onchain analysts including BlockWatchdog and Specter Investigations, not by a disclosure from Coinsbuy.

Where the money went
Roughly 79% of the stolen funds passed through instant exchange FixedFloat across about 50 single-use addresses, a pattern that breaks a large sum into fragments no single compliance team sees in full. Portions were then converted into Monero.
Monero is a cryptocurrency that conceals sender, receiver and amount by default, which makes the standard tracing tools used by exchanges and investigators largely ineffective against it. Once value crosses into Monero, recovery odds drop sharply.
Not all of it got away. ChangeNOW froze a six-figure sum after Specter Investigations made contact, and about 282 ETH worth roughly $542,000 across five addresses has not moved. Those balances are the most likely target of any recovery effort.
What the 24-hour refill signals
Coinsbuy topped the drained wallets back up to within 0.05% of their pre-attack balances inside a day, behavior researchers read as evidence the company does not believe its private keys were stolen. Sending fresh funds to an address an attacker still controls would simply hand over a second payment.
That points the investigation toward the authorization layer rather than key custody, meaning whatever system approves and signs outgoing transfers rather than the secrets themselves. Coinsbuy briefly suspended deposits and withdrawals before restoring both, and told CoinDesk the incident had been contained, that all affected amounts were covered from its own reserves, and that no client bore a loss.
The company has not published a technical postmortem, so the read on private keys remains an inference from wallet behavior rather than a confirmed finding. The attack vector is still unestablished.
Why merchant payment platforms keep getting hit
Coinsbuy sells crypto payment processing to businesses and merchants rather than retail trading, a model that requires holding spendable balances on several chains at once so settlements clear on demand. That design concentrates value in hot infrastructure and gives an attacker who reaches the withdrawal layer more than one chain to work with, which is exactly the shape of the Aug. 9 drain.
The incident lands in a year that had already seen roughly $972 million stolen across the sector through late July, by CoinDesk’s count. Recent months brought a $11.8 million treasury wallet hack at Singapore payment firm Triple-A, a Coldcard firmware flaw that drained 594 BTC, and a BTCPay Server credential flaw that emptied Lightning nodes earlier this week. None involved a base-layer protocol failure. All involved the software and key-handling built around it.
What to watch next: whether investigators can freeze more of the 282 unmoved ETH, whether Coinsbuy publishes a postmortem naming the vector, and whether merchants using multi-chain processors start asking who signs outbound transfers and what approvals that signature requires.
Frequently asked questions
How much did the Coinsbuy hack cost?
The attacker took $8.07 million on Aug. 9, split between 6.04 million USDT from eight Tron wallets and 1.89 million USDT plus 77 ETH from three Ethereum wallets. Coinsbuy said it covered the full amount from its own reserves and that no customer lost money.
Were Coinsbuy customer funds affected?
Coinsbuy said no client bore a loss and that the platform is operating normally. Deposits and withdrawals were briefly suspended after the drain and then restored. The company refilled the affected wallets to within 0.05% of their pre-attack balances within 24 hours.
Can the stolen crypto be recovered?
Partly. ChangeNOW froze a six-figure sum and about 282 ETH worth $542,000 has not moved. The roughly 79% routed through FixedFloat and converted into Monero is far harder to trace, since Monero hides transaction details by default. Recovery in these cases usually depends on exchanges freezing funds before they are converted.








